CVE-2009-1490
medium · 5Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
5
CVSS
12.6%
EPSS (exploit prob.)
96th
EPSS percentile
2009-05-05
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sendmail | sendmail | <= 8.13.1.2 |
| sendmail | sendmail | 2.6 |
| sendmail | sendmail | 2.6 |
| sendmail | sendmail | 2.6.1 |
| sendmail | sendmail | 2.6.1 |
| sendmail | sendmail | 2.6.2 |
| sendmail | sendmail | 3.0 |
| sendmail | sendmail | 3.0 |
| sendmail | sendmail | 3.0.1 |
| sendmail | sendmail | 3.0.1 |
| sendmail | sendmail | 3.0.2 |
| sendmail | sendmail | 3.0.2 |
| sendmail | sendmail | 3.0.3 |
| sendmail | sendmail | 4.1 |
| sendmail | sendmail | 4.55 |
| sendmail | sendmail | 5 |
| sendmail | sendmail | 5.59 |
| sendmail | sendmail | 5.61 |
| sendmail | sendmail | 5.65 |
| sendmail | sendmail | 8.6.7 |
| sendmail | sendmail | 8.7.6 |
| sendmail | sendmail | 8.7.7 |
| sendmail | sendmail | 8.7.8 |
| sendmail | sendmail | 8.7.9 |
| sendmail | sendmail | 8.7.10 |
| sendmail | sendmail | 8.8.8 |
| sendmail | sendmail | 8.9.0 |
| sendmail | sendmail | 8.9.1 |
| sendmail | sendmail | 8.9.2 |
| sendmail | sendmail | 8.9.3 |
| sendmail | sendmail | 8.10 |
| sendmail | sendmail | 8.10.0 |
| sendmail | sendmail | 8.10.1 |
| sendmail | sendmail | 8.10.2 |
| sendmail | sendmail | 8.11.0 |
| sendmail | sendmail | 8.11.1 |
| sendmail | sendmail | 8.11.2 |
| sendmail | sendmail | 8.11.3 |
| sendmail | sendmail | 8.11.4 |
| sendmail | sendmail | 8.11.5 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-1490